All skills
automattic avatar

/wp-phpstan

@4904f8c official
by automatticautomattic/agent-skills211 stars
37

Use when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and handling third-party plugin classes.

Use this Skill: https://skilld.dev/gh/automattic/agent-skills/wp-phpstan

This session only. Nothing lands on disk.

referencesconfiguration.md

≈342 tokens on demand. Your agent reads this file only when SKILL.md points to it.

PHPStan configuration (WordPress)

This reference documents a minimal, WordPress-friendly PHPStan setup and baseline workflow.

Minimal phpstan.neon template

Use the repo’s existing layout. The example below is intentionally conservative and should be adapted to the project’s actual directories.

# Include the baseline only if the file exists.
includes:
    - phpstan-baseline.neon

parameters:
    level: 5
    paths:
        - src/
        - includes/

    excludePaths:
        - vendor/
        - vendor-prefixed/
        - node_modules/
        - tests/

    ignoreErrors:
        # Add targeted exceptions only when necessary.

Guidelines:

  • Prefer analyzing first-party code only.
  • Exclude anything generated or vendored.
  • Keep ignoreErrors patterns narrow and grouped by dependency.

Baseline workflow

Baselines help you adopt PHPStan in legacy code without accepting new regressions.

# Generate a baseline (explicit filename)
vendor/bin/phpstan analyse --generate-baseline phpstan-baseline.neon

# Update an existing baseline (defaults)
vendor/bin/phpstan analyse --generate-baseline

Best practices:

  • Avoid adding new errors to the baseline; fix the new code instead.
  • Treat baseline changes like code changes: review in PRs.
  • Chip away at the baseline gradually (remove entries as you fix root causes).

Source: SKILL.md on GitHub

1 warning17d4 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    The skill provides standard guidance and a local utility script for configuring and running PHPStan static analysis in WordPress projects. It recommends using well-known community stubs and follows best practices for development tooling. No security issues were detected.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    3/5 files flagged

Signed by skilld at 4904f8c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 5 months ago.

Dormantupdated 9 months ago
compatibility
Targets WordPress 6.9+ (PHP 7.2.24+). Requires Composer-based PHPStan.
  • wordpress
  • phpstan
  • static-analysis
  • php
  • type-checking
  • composer
  • plugins
  • themes
  • php-stubs

README badge

README badge for automattic/agent-skills/wp-phpstan

Configures and runs PHPStan static analysis in WordPress projects, handling phpstan.neon setup, baselines, WordPress-specific type annotations, and third-party plugin classes. Targets WordPress 6.9+ with Composer-based PHPStan and includes helpers for REST endpoints, hook callbacks, and database query typing.

Generated from the current SKILL.md.

Does this skill work with WordPress versions before 6.9?
No. The skill targets WordPress 6.9+ with PHP 7.2.24+. Older versions may have different typing patterns and stub compatibility.
What WordPress stubs package does this skill assume?
The skill expects either szepeviktor/phpstan-wordpress or php-stubs/wordpress-stubs to be installed. Without stubs, you'll see many errors about unknown WordPress core functions.
Can this skill fix PHPStan errors in third-party plugins integrated into my codebase?
The skill handles third-party plugin/theme classes by using plugin-specific stubs (like php-stubs/woocommerce-stubs) or targeted ignore patterns, but prefers not to analyze code outside your first-party directories.
Does this skill generate or modify phpstan-baseline.neon?
Yes, the skill can generate or update baselines, but treats baselines as a migration tool for legacy code—not a way to suppress newly introduced errors. Baseline changes require user permission.
What input do I need to provide before using this skill?
You should run wp-project-triage first, and confirm whether the user allows adding Composer dev dependencies (stubs) and changing the baseline for the task.

Generated from the current SKILL.md. These answers refresh after source changes.